Position Summary:
Under minimal supervision, as a member of the R&D Software Engineering team at Werfen, this role focuses on both offensive and defensive cybersecurity, as well as operational security. The primary responsibilities include identifying and validating vulnerabilities, mitigating risks, and ensuring compliance with regulatory standards to safeguard critical systems in highly regulated industries using software engineering tools and techniques available.
ResponsibilitiesEssential Functions:
Participates as active member of the project team focusing on analyzing penetration test results, assessing attack patterns and severity, and collaborating with Red or developersProvide actionable remediation guidance to mitigate identified cybersecurity defects and risks.Manage and maintain vulnerability scanning tools, and secure test environments.Conduct fuzz testing to uncover unknown vulnerabilities and escalate critical findings.Reproduce and validate cybersecurity defects in controlled environments.Evaluate, Investigate and resolve cybersecurity issues/ fixes reported by customers, ensuring effective and timely solutions.Produce high-quality technical documentation to support compliance with regulatory standards such as FDA, HIPAA, and ISO 13485.Collaborate with development, IT, and product teams to ensure secure design and implementation of systems and products.Creates/Maintains software requirement/functional specificationsIdentifies interfaces between software components and/or hardwareCreates/Maintains software (component) design documentationCreates/Maintains software source code that adheres to design documentationPerforms unit testing and/or code reviews as per project policyPerforms integration testing to ensure software functions within application and with devicesEvaluates, investigates, and implements fixes to assigned software defectsEvaluates, investigates, and implements assigned software change proposalsKey Relationships:
To be determined based on department needs, to include interactions such as:
Provides level of effort for assigned software activitiesTracks personal estimates over time in order to improve accuracyEffectively communicates technical information to a multidisciplinary team in the form of documentation, presentations and technical summaries.Makes recommendations or suggestions for department improvementsAbility to work in a team environment of software developers and testersSkills & Capabilities:
The ideal candidate for this position will exhibit the following skills and capabilities:
Expertise in penetration testing tools (e.g., Nessus, Metasploit, Burp Suite) and fuzzing tools (e.g., Peach, AFL).Familiarity with secure software development lifecycles (SDLC).Familiarity with standards such as FDA, HIPAA, and ISO 13485.Strong technical writing skills for compliance, reporting, and regulatory submissions.Advanced knowledge in exploit chaining and vulnerability analysis.Industry-recognized certifications such as OSCP, CEH, GPEN, or equivalent.Experience with VMware ESXi and virtualized environments desirable.Strong knowledge of Linux systems.Experience in cybersecurity for medical devices or other highly regulated industries.Strong written and oral communications skillsAbility to use software engineering tools: configuration, requirements, and defect managementAbility to operate instrumentation QualificationsMinimum Knowledge & Experience Required for the Position:
Education:
Associates Degree plus typically 4 to 10 years of related experience or Bachelor’s Degree plus typically 4 to 8 years of related experience or Master’s Degree plus typically 2 to 6 years of related experience or waiver based on experience. Degree should be in a technical discipline such as Chemistry, Math, Physics, Engineering, or Computer Science.Experience:
Programming expertise in Python, Bash, C, or C++.Hands-on expertise in offensive and defensive security and penetration testing methodologies.Additional Skills/Knowledge:
Proficiency with a personal computer and software packagesAbility to use software engineering tools: configuration, requirements, and defect managementAbility to handle many software componentsLanguage: EnglishTravel Requirements:
< 5% of the time Options Apply for this job onlineApplyShareRefer a friendRefer Sorry the Share function is not working properly at this moment. Please refresh the page and try again later. Share on your newsfeed Application FAQsSoftware Powered by iCIMS
www.icims.com